Tagged Content
Everything on the platform tagged with supply-chain-security.
Semgrep is a San Francisco application-security company that builds a unified AppSec platform (Code/SAST, Supply Chain/SCA, and Secrets) used by engineering teams at Dropbox, Figma, Snowflake and others. Born out of an open-source tool originally written at Facebook, it lets security teams write code-like rules and ship them through CI - cutting false positives and pushing fixes back to developers.

Russ Cox is a Distinguished Engineer at Google and the longtime technical lead of the Go programming language, the open-source language he helped shape for over a decade. Known for foundational work on RE2 (a safe, linear-time regex engine), Plan 9 from User Space, and Go's module system, he bridges deep computer science theory with production-grade engineering. After stepping down as Go tech lead in September 2024, he shifted focus to AI-powered open source tooling - building Gaby and Oscar, agent systems designed to help maintainers with the unglamorous but essential work of keeping software alive.

Sylvain Kerkour is a French software engineer, security researcher, and author best known for 'Black Hat Rust' - a hands-on book applying offensive security techniques with the Rust programming language. Self-described as a 'professional troublemaker', he writes about programming, hacking, and entrepreneurship at kerkour.com under the tagline '(Ab)using technology for fun & profit'. He is a vocal advocate for supply chain security in the Rust ecosystem and creator of the Bloom open-technology platform and the ChaCha20-BLAKE3 AEAD cipher implementation.